Use-after-free in Linux kernel - CVE-2026-74660
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the ebt_nflog netfilter target when processing packets that match an ebtables nflog rule during concurrent unloading of the nfnetlink_log module. A local user can trigger packet logging through a crafted ebtables nflog rule to cause a denial of service.
Exploitation requires a race with module teardown while an ebtables nflog rule remains callable.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74660
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/2cac4294f184c9bc19ff82552c62b80498694c39
- https://git.kernel.org/stable/c/30825970339c107bacaf7f61af90fcdb1f597ca1
- https://git.kernel.org/stable/c/394d7939c6b2b9e6bea0844c89efb5913168d898
- https://git.kernel.org/stable/c/3bcce49d617c593c7606083bfdb464a1761fa68d
- https://git.kernel.org/stable/c/47a119ec8a7e2d5c8c4e86fb1a56c4e696e500fb
- https://git.kernel.org/stable/c/6809379a860b9fccbb5435bf08343f6d081ac68d
- https://git.kernel.org/stable/c/9d8a94b48b393885e7f876c8ef68ed4da5012078
- https://git.kernel.org/stable/c/e2ab7e878bdbe80104c879c31fd2d82a476703b8